Skip to main content

Vendor/product archive

tgstation13 / tgstation-server CVEs

Beta · best-effort

7 CVEs tagged to tgstation13 / tgstation-server1 Critical, 4 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2025-21611

Published Jan 6, 2025

tgstation-server is a production scale tool for BYOND server management. Prior to 6.12.3, roles used to authorize API methods were incorrectly OR'd instead of AND'ed with the role…

CVSS 8.8 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2024-41799

Published Jul 29, 2024

tgstation-server is a production scale tool for BYOND server management. Prior to 6.8.0, low permission users using the "Set .dme Path" privilege could potentially set malicious .…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34243

Published Jun 8, 2023

TGstation is a toolset to manage production BYOND servers. In affected versions if a Windows user was registered in tgstation-server (TGS), an attacker could discover their userna…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33198

Published May 30, 2023

tgstation-server is a production scale tool for BYOND server management. The DreamMaker API (DMAPI) chat channel cache can possibly be poisoned by a tgstation-server (TGS) restart…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32687

Published May 29, 2023

tgstation-server is a toolset to manage production BYOND servers. Starting in version 4.7.0 and prior to 5.12.1, instance users with the list chat bots permission can read chat bo…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-16136

Published Jul 31, 2020

In tgstation-server 4.4.0 and 4.4.1, an authenticated user with permission to download logs can download any file on the server machine (accessible by the owner of the server proc…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17107

Published Sep 24, 2018

In Tgstation tgstation-server 3.2.4.0 through 3.2.1.0 (fixed in 3.2.5.0), active logins would be cached, allowing subsequent logins to succeed with any username or password.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1